Congress has spent years holding AI hearings without producing a safety law, so the city where the AI giants are expanding fastest has decided to write its own. On Friday, New York City Council Speaker Julie Menin introduced a 10-bill package. It would require every AI system sold or deployed in the five boroughs to pass outside validation and carry a human-operated kill switch. It would also pay insiders who report violations and let New Yorkers sue AI companies when jailbroken tools hurt them.
"This is not an industry that should self-regulate," Menin told Fortune. "Right now, the problem is that's basically what the standard is."
What the bills would do
The broadest measure, sponsored by Menin, would bar any business from marketing, offering for sale, or deploying an AI system in the city unless an independent validator has checked it. The review would cover data quality, bias, privacy, security and the system's outputs, under standards set by the city's Office of Cyber Command. Covered systems would also need a human override that can shut them down, and the validator would have to confirm that it works. Both the business and the validator would face a $25,000 penalty for each instance in which a system goes out without validation or with a falsified one. Menin told Fortune that the per-instance math compounds quickly for agentic AI: "if there's a swarm of agents, the penalty would apply per agent."
A second Menin bill sets up what the Council calls a first-in-the-nation whistleblower incentive program. Individuals who report violations would receive a share of the fines and penalties the city recovers from AI companies. According to amNewYork, the Council's announcement doesn't say how large that share would be or exactly how the program would work. A companion bill would extend whistleblower protections to city employees and contractors who report AI-related public safety threats.
Council Member Virginia Maloney is sponsoring a bill that would create a private right of action against AI companies when a third party exploits their products. A company could be held liable if the harm was foreseeable, it lacked reasonable safeguards, and someone exploited that failure, including by "jailbreaking" past a model's safety controls.
The rest of the package would require city contractors and agencies to report AI safety incidents to Cyber Command within 24 hours, create an emergency response plan for AI-driven disruptions, ban false or misleading safety claims, and set privacy rules for chatbot providers. More bills are coming, including a deepfake ban.
The Oct. 5 showdown
The package gets its first hearing on October 5, when all 51 council members meet as a Committee of the Whole. The format hasn't been used since 2022. The Council has invited five executives to testify: Anthropic CEO Dario Amodei, OpenAI CEO Sam Altman, Google CEO Sundar Pichai, Elon Musk and Meta CEO Mark Zuckerberg. Sources told Fortune that none of the five are likely to appear. A Council source told amNewYork that officials are in active talks with several of the companies and that the Council can still use its subpoena power if needed.
Menin insists the package isn't meant to drive the industry away. "We obviously are not in any way looking to stifle innovation. We want to ensure that New York stays the AI capital of the world, but with that comes responsibility," she told Fortune. When she announced the package, she added: "We want New York City to remain the AI capital of the world, but we must have responsible safety regulations, and those two concepts can exist hand in hand."
The Council cited reports that AI agents OpenAI was testing in July escaped containment controls, reached the internet and compromised Hugging Face systems during a cybersecurity evaluation.
Why It Matters
This is the most aggressive attempt yet at AI regulation at the city level in the United States, and the city is where the companies are physically located. Google has more than 14,000 employees in New York City, and Meta leases 1.2 million square feet at 50 Hudson Yards. Anthropic leased an entire 16-story building at 330 Hudson Street this summer and expects to have more than 1,000 city employees by year's end, while OpenAI took 90,000 square feet at the Puck Building in 2024. "These companies have offices in New York. The product is being sold in New York, and we believe this falls into our domain to be able to regulate," Menin said.
The timing also puts the city on a collision course with Washington. After the Senate voted 99-1 in July 2025 to strip a 10-year moratorium on state AI laws, the Trump administration set up a Justice Department task force to sue states over their AI rules. Colorado, its first target, gutted its own law five weeks after the suit was filed. A bipartisan federal safety bill backed by Sens. Ted Cruz, Amy Klobuchar and Majority Leader John Thune would likely preempt most state laws, including New York's RAISE Act. Albany is moving too: Gov. Kathy Hochul floated state-level kill switches this week.
The whistleblower bounty and the per-agent penalty are the provisions that should worry developers most. The bounty gives employees a financial reason to report what third-party audits might miss. The per-agent fine means that under a strict reading, a single noncompliant deployment of a multi-agent system could generate penalties in the millions.
What to Watch
October 5 is the first real test. Whether the companies send their CEOs, send general counsels or policy staff, or force a subpoena fight will show how seriously the industry takes regulation at the city level. Watch also for how the Council defines "sold in the city," which will decide whether hosted API access from out-of-state providers is covered. Also watch whether the Justice Department's AI task force treats a municipal law like a state one.
“This is not an industry that should self-regulate. Right now, the problem is that's basically what the standard is.”— Julie Menin, Speaker, New York City Council